CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5488  CVE-2002-1101  Candidate  Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.  Proposed (20030317)  ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | REVIEWING(1) Christey  Christey> Possible dupe of CVE-2002-1100 ?? Need to review the bug log | in the Cisco advisory.  View
2644  CVE-2000-1076  Candidate  Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.  Proposed (20001129)  ACCEPT(3) Baker, Frech, Mell | NOOP(2) Christey, Cole  Christey> Partial vendor acknowledgement at: | http://docs.iplanet.com/docs/manuals/cms/42/relnotes/release_notes.html | "By default, Administration Server administrator"s password | (also known as the SIE password) is stored in clear text in the | adm.conf file. | This does not usually pose a security threat because most | administrators use their Operating System"s security features to | ensure that the file is protected from other users."  View
5332  CVE-2002-0944  Candidate  Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.  Modified (20030325-01)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Christey, Cox, Foat, Wall  Christey> On February 19, 2003, DeepMetrix confirmed via email that this | bug has been corrected in LiveStats 6.2.2. | | CONFIRM:http://www.deepmetrix.com/log_analyzer/xsp/service/release_notes/index.asp | | As of February 19, this URL only mentions the User-Agent bug, | but the vendor again confirmed via email that the referrer is | also addressed.  View
7637  CVE-2003-0813  Candidate  A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.  Assigned (20030918)  NOOP(1) Christey  Christey> Note: MS04-012 references this CAN and credits eEye, who | describes a similar-looking issue in their advisory COMMENT | "AD20040413A." However, this particular candidate was published by | ISS in 2003. MITRE is investigating this discrepancy and will update | this candidate if necessary.  View
5646  CVE-2002-1262  Candidate  Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files.  Proposed (20030317)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> NOTE: Early versions of Microsoft bulletin MS02-069 | also assigned for a "user.dir exposure" issue. This | candidate should *ONLY* be used for the external caching issue | as covered in MS:MS02-068; the "user.dir" issue is identified | by CVE-2002-1365.  View

Page 294 of 20943, showing 5 records out of 104715 total, starting on record 1466, ending on 1470

Actions